Step-by-Step Palo Alto Windows User-ID Agent Setup Guide [2024]

  Рет қаралды 15,247

NETSums

NETSums

Күн бұрын

Пікірлер: 34
@netsums
@netsums Жыл бұрын
FREE Palo Alto Cheat Sheet in different formats and further FREE resources: netsums.com/resources
@maozkaufmann5255
@maozkaufmann5255 2 ай бұрын
You are amazing. Funny to think nobody in this world has provided updated videos on how to do things with Palo Alto.
@netsums
@netsums Ай бұрын
Thank you for the comment, I'm glad you like the videos!
@jmanc2179
@jmanc2179 Сағат бұрын
Thank you great content! If you use the default management interface for communications then no need for rules to allow communications between windows user ID agent server and Palo firewall right?
@RishiRap
@RishiRap 11 ай бұрын
As usual, Great content! Always looking forward to your new meaningful and informational videos.
@netsums
@netsums 11 ай бұрын
Thank you for the comment, I'm glad you liked the video!
@TariqASheikh
@TariqASheikh 7 күн бұрын
Would be useful to have link for all pre-requisites etc.
@netsums
@netsums 7 күн бұрын
You're right. I'll take a look at it soon. Thank you!
@diwakarkumar3216
@diwakarkumar3216 Жыл бұрын
Love from India. ❤ Your are doing great contribution for upcoming generation. Please make full course video. It will be helpful if you help me in enabling Google authenticator in GP-VPN❤❤❤
@netsums
@netsums 11 ай бұрын
Thank you for the lovely comnent, I will try!
@smakersify
@smakersify 10 ай бұрын
Excellent buddy, subbed
@netsums
@netsums 10 ай бұрын
Thank you! I'm glad you liked it!
@diwakarkumar3216
@diwakarkumar3216 Жыл бұрын
Please keep making videos on all topics
@netsums
@netsums 11 ай бұрын
I will try my best!
@normannueno2872
@normannueno2872 4 ай бұрын
Awesome!!!
@netsums
@netsums 4 ай бұрын
Thank you, I'm glad you liked the video. 😊
@blackknight985
@blackknight985 6 ай бұрын
Excellent video! just a quick question, how did you get rid of the warning message about API Key after committing the changes?
@netsums
@netsums 6 ай бұрын
Can you post here the warning message you're getting?
@RishiRap
@RishiRap 11 ай бұрын
You configured a security policy with zone "lab2" for both src and dst close to 9.50 timeline. Isn't Intra-zone policy is default and allows "all"? Please clarify. Thanks.
@netsums
@netsums 11 ай бұрын
You're 100% correct, this rule wouldn't be necessary with standard default rules. But I personally am not a big fan of intra-zone allow as default, so I have in my lab an override with a deny for my intra-zone default rule. So I had to add this rule. But nice caught! :-)
@fisa6835
@fisa6835 4 ай бұрын
Hallo, I'd like to ask, can I use this way to allow users that already join domain (AD users) to bypass captive portal and non ad users has to go to captive portal?
@juliaperez9958
@juliaperez9958 4 ай бұрын
Thank you, this is very helpful. With this setup, user mapping is working, but server monitoring under User-Identification-user mapping isn't. Do you have any suggestions to get server monitoring to work
@netsums
@netsums 4 ай бұрын
Thank you for the comment. You don't need to configure anything in the server monitoring if you have a windows based User-ID agent. If you are trying to configure the PAN-OS User-ID agent, I would suggest you to think about the windows based agent, in my experience it's a lot less problematic to setup.
@juliaperez9958
@juliaperez9958 4 ай бұрын
@@netsums Thank you very much for the advice. I will give that a try.
@brianleb
@brianleb 3 ай бұрын
How would I setup multiple firewalls to use the CA generated on one firewall?
@brianleb
@brianleb 3 ай бұрын
Answer is to export the CA cert from the originating firewall and then import it on each additional PA and setup the in a Cert Profile and attach that to the UserID Connection Security
@ADempsey
@ADempsey 3 ай бұрын
If we use a public cert from globalsign will it be generated on the UserID server or from the Palo?
@netsums
@netsums 3 ай бұрын
You need to install the certificate on the User-ID server.
@潘群崴
@潘群崴 2 ай бұрын
Sorry to bother you, but I have a question. I have completed the User ID Agent configuration, and I can see the user information under MONITOR > User ID. However, only the user information is currently displayed. How can I configure it to display the group information as well?
@netsums
@netsums 2 ай бұрын
Hi. You probably need gouo mapping. Take a look at this video, there is a session there that I show how it can be configured: kzbin.info/www/bejne/hoapYpt3e5tjd7ssi=sKaytILFlLi2klYD Let me know later if the video could help you solve the problem. :-)
@Domesteron1998
@Domesteron1998 10 ай бұрын
Idk what is wrong, for me not working redestribute status is "No"..
@netsums
@netsums 9 ай бұрын
Sorry for the late reply. Hard to say, many reasons: - Port 5007 not being allowed - Certificate not bein able to validate (does it work without certificate validation?). Use Packet Capture to debug it - Pre-shared Key not matching... What error messages are you receiving?
@KyleLilleyBPS
@KyleLilleyBPS 7 ай бұрын
@@netsums **excellent** video, worked perfectly. only extra thing related to this fellas question is we needed to add a windows firewall rule to allow the 5007 traffic before it would allow the communication
@netsums
@netsums 7 ай бұрын
Thank you for the reply!
Palo Alto URL Filtering and URL Categories
15:48
NETSums
Рет қаралды 6 М.
За кого болели?😂
00:18
МЯТНАЯ ФАНТА
Рет қаралды 3,4 МЛН
From Small To Giant 0%🍫 VS 100%🍫 #katebrush #shorts #gummy
00:19
Кто круче, как думаешь?
00:44
МЯТНАЯ ФАНТА
Рет қаралды 6 МЛН
Palo Alto Lesson: 9.8 Lab: User-ID
27:40
Astrit Krasniqi
Рет қаралды 8 М.
Setting Up Destination NAT in VPN Tunnel - Palo Alto - SonicWall Firewall
19:03
Taylormadevacation Rental
Рет қаралды 283
Cisco Firewall Quick Start Guide (Firepower 1010 setup)
37:27
David Bombal Tech
Рет қаралды 33 М.
Palo Alto GlobalProtect VPN Configuration [2024 IMPROVED!!!]
27:19
TCP/IP for Programmers
3:03:31
Eli the Computer Guy
Рет қаралды 231 М.
When to use Pre and Post Security Rules in Panorama
12:00
NETSums
Рет қаралды 6 М.
Palo Alto - Temporarily Block Attackers [2024]
16:25
NETSums
Рет қаралды 2,4 М.
За кого болели?😂
00:18
МЯТНАЯ ФАНТА
Рет қаралды 3,4 МЛН